Skip to main content
EPSS 18.2%top 3.0%

A view on a recent Salt Typhoon intrusion

0
Medium
Published: 10/20/2025 (10/20/2025, 15:21:15 UTC)
Source: AlienVault OTX General

Description

Salt Typhoon, a China-linked cyber espionage group, exploited a zero-day vulnerability (CVE-2024-40766) in Citrix NetScaler Gateway appliances to target a European telecommunications organization. The attackers used DLL sideloading to deploy the SNAPPYBEE backdoor and leveraged LightNode VPS endpoints for command and control. The intrusion involved lateral movement from the compromised gateway to Citrix VDA hosts with the intent of data exfiltration. Darktrace detected the attack early through anomaly-based detection, enabling containment before significant damage occurred. No known exploits are currently in the wild. The threat demonstrates sophisticated stealth techniques by state-sponsored actors targeting critical infrastructure. Organizations using Citrix infrastructure, especially in telecommunications, should monitor proactively and apply patches when available. The suggested severity is medium due to the targeted nature and exploitation complexity.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/23/2026, 03:09:20 UTC

Technical Analysis

The Salt Typhoon group exploited a zero-day vulnerability identified as CVE-2024-40766 in Citrix NetScaler Gateway appliances. They employed DLL sideloading to install the SNAPPYBEE backdoor and used LightNode VPS endpoints for command and control communications. After initial compromise, the attackers pivoted to Citrix VDA hosts aiming to exfiltrate data. Detection was achieved early by Darktrace's anomaly-based methods, which allowed containment before major impact. There are currently no known exploits in the wild for this vulnerability. The attack highlights advanced tactics by a state-sponsored actor targeting telecommunications infrastructure. No patch status is provided, and affected versions are not specified.

Potential Impact

Successful exploitation allows attackers to deploy a persistent backdoor (SNAPPYBEE) on Citrix NetScaler Gateway appliances, enabling command and control via LightNode VPS endpoints. The attackers can pivot within the network to Citrix VDA hosts, potentially leading to data exfiltration. The compromise threatens confidentiality and availability of targeted telecommunications infrastructure. However, early detection and containment prevented significant damage in the observed incident. No widespread exploitation is currently reported.

Defensive Guidance

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Organizations should prioritize proactive monitoring of Citrix NetScaler Gateway appliances for anomalous activity, especially related to DLL sideloading and unusual network communications. Apply vendor patches promptly once available. Early detection tools that use anomaly-based methods can be effective in identifying such intrusions. No known exploits are currently in the wild, reducing immediate urgency but maintaining vigilance is advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://www.darktrace.com/blog/salty-much-darktraces-view-on-a-recent-salt-typhoon-intrusion"]
Adversary
Salt Typhoon
Pulse Id
68f6536b549a38d68528a530

Indicators of Compromise

Hash

ValueDescriptionCopy
hash8bd8506f6b1a80eea68e877fa81e267c
hashb5367820cd32640a2d5e4c3a3c1ceedbbb715be2
hashfc3be6917fd37a083646ed4b97ebd2d45734a1e154e69c9c33ab00b0589a09e5

Ip

ValueDescriptionCopy
ip156.244.28.153
ip38.54.63.75

Url

ValueDescriptionCopy
urlhttp://137.184.126.86:8080/vmwaretools
urlhttp://156.244.28.153/17ABE7F017ABE7F0
urlhttp://89.31.121.101:443//Dialog.dat
urlhttp://89.31.121.101:443/DisplayDialog.exe
urlhttp://89.31.121.101:443/NortonLog.txt
urlhttp://89.31.121.101:443/dbindex.dat
urlhttp://89.31.121.101:443/imfsbDll.dll
urlhttp://89.31.121.101:443/imfsbSvc.exe

Domain

ValueDescriptionCopy
domainaar.gandhibludtric.com

Threat ID: 68f75555159af2a541b9f98d

Added to database: 10/21/2025, 09:41:41 UTC

Last enriched: 06/23/2026, 03:09:20 UTC

Last updated: 09/10/2026, 19:36:48 UTC

Views: 894

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses